Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2023-38037
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
ActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file. The temporary file's permissions are defaulted to the user's
current `umask` settings, meaning that it's possible for other users on the
same system to read the contents of the temporary file.
Attackers that have access to the file system could possibly read the contents
of this temporary file while a user is editing it.
All users running an affected release should either upgrade or use one of the
workarounds immediately.
0
Attacker Value
Unknown
CVE-2023-28120
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
0
Attacker Value
Unknown
CVE-2023-22796
Disclosure Date: February 09, 2023 (last updated October 08, 2023)
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
0
Attacker Value
Unknown
CVE-2018-3779
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2010-2911
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
0
Attacker Value
Unknown
CVE-2010-2912
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
0
Attacker Value
Unknown
CVE-2010-0460
Disclosure Date: January 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-3567
Disclosure Date: October 06, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145.
0
Attacker Value
Unknown
CVE-2008-4761
Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.
0
Attacker Value
Unknown
CVE-2007-6513
Disclosure Date: December 21, 2007 (last updated October 04, 2023)
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
0